SECURITY·중요도 8·2026. 07. 28.·The Hacker News
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
── KO ──────────────────
Tengu 봇넷은 프로세스 종료 시 리부팅 기능을 이용해 방어를 회피합니다.
Tengu는 Mirai에서 파생된 봇넷으로, 손상된 리눅스 장치의 하드웨어 와치독을 사용하여 방어자들이 메인 프로세스를 종료할 경우 리부팅을 유도합니다. 이렇게 되면 Tengu의 다른 지속성 메커니즘이 다시 실행될 기회를 얻습니다. 이 봇넷은 텔넷 자격 증명 브루트 포스를 통해 목표 장치에 침투할 수 있습니다.
── EN ──────────────────
The Tengu botnet evades defenses by rebooting compromised Linux devices when its process is killed.
Tengu is a new Mirai-derived botnet that utilizes a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. This allows Tengu's other persistence mechanisms another chance to launch. The botnet has been observed reaching its honeypots through Telnet credential brute force attacks.